BitcoinMarkets newsNews

Trezor phishing attack traced to Brevo login authorization flaw

An authorization flaw in Brevo’s login system has allowed an attacker to access 138 customer accounts, leading to phishing emails sent through accounts used by Trezor, BitBox and CoinTracking.

Summary
  • A Brevo login flaw gave an attacker access to 138 customer accounts, including those used by Trezor, BitBox and CoinTracking.
  • Phishing emails were sent through six accounts, while contact lists were exported from 43 accounts.
  • A fraudulent Trezor email reached roughly 347,000 subscribers and sent around 2,500 people to a malicious link.
  • Trezor is treating all 347,000 newsletter addresses as potentially known to the attacker and reusable for phishing.

Brevo said in a Thursday postmortem that the attacker exploited a weakness involving its single sign-on system, gaining access to organizations connected to legitimate users who had been invited into an attacker-controlled Brevo account.

The incident affected 138 customer accounts in total. Six were used to send phishing emails, contacts were exported from 43 accounts, while Brevo recorded no meaningful activity across another 93. The company did not specify whether those groups overlapped.

Brevo flaw gave attacker access to customer organizations

Brevo traced the incident to the way its platform handled permissions when users belonged to more than one organization.

The attacker first created a Brevo account and enabled single sign-on before inviting legitimate Brevo users into the newly created organization. Access should have remained limited to the attacker-controlled organization.

Instead, Brevo said an authorization boundary failed, allowing the attacker to reach every organization that the invited users themselves had permission to access.

The compromised accounts included those used by hardware wallet makers Trezor and BitBox and crypto portfolio tracking and tax-reporting service CoinTracking. Access to the legitimate email infrastructure allowed fraudulent messages to be distributed in a way that made them look like normal company communications.

The disclosure provides the technical explanation behind the phishing emails targeting Trezor and BitBox customers this week. Crypto.news previously reported that both hardware wallet companies warned users on Wednesday after identifying fraudulent security messages distributed through a third-party newsletter provider.

Because the messages were sent through legitimate mailing infrastructure, they could pass normal email authentication checks and reach subscribers from addresses associated with the affected companies.

Trezor’s phishing email used the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and presented a supposed hardware security problem that required users to take action.

The message directed recipients to a malicious application that requested their wallet backups. Anyone who obtains a wallet recovery phrase can recreate the corresponding wallet and gain control over its funds.

Trezor phishing email reached 347,000 subscribers

Trezor said its Brevo account contained roughly 347,000 opt-in newsletter email addresses, with no other customer information stored on the platform.

A Trezor spokesperson told Cointelegraph that the initial phishing message was sent to all 347,000 addresses. The company subsequently contacted the same subscribers to warn them about the attack.

Trezor took the malicious domain offline at the DNS level within 20 minutes. Around 2,500 people had accessed the link before the takedown, according to the company.

“Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing,” the spokesperson said.

Trezor said the Brevo incident did not compromise its hardware wallets, wallet backups or other internal systems. Customers who did not enter their wallet backup into the malicious application remained safe, according to the company.

The campaign follows several other phishing attempts involving the hardware wallet maker. In August, a Trezor user said he lost his life savings after a sponsored Google search result directed him to a fake website hosted through Google Sites.

Trezor said at the time that it was seeing more phishing websites impersonating the company through sponsored search results and warned customers never to enter wallet backups on websites.

Earlier in 2026, scammers took the impersonation attempts offline by sending fake Trezor and Ledger letters to hardware wallet owners. The letters contained QR codes leading to phishing websites that requested 12, 20 or 24-word recovery phrases under the pretext of completing authentication or transaction checks.

BitBox and CoinTracking accounts used in phishing wave

BitBox identified a similar campaign on Wednesday and warned users not to follow instructions contained in fraudulent emails sent under its name.

Its initial investigation found that several Bitcoin companies had been targeted and appeared to share the same newsletter provider. BitBox contacted the provider, warned newsletter subscribers and reported the phishing domains while investigating how the emails had been distributed.

The attack came weeks after BitBox patched two wallet vulnerabilities involving firmware installation and Bitcoin address handling. BitBox said there was no known exploitation of either flaw and reported no stolen user funds.

CoinTracking customers received a different phishing lure designed around the service’s portfolio tracking and tax-reporting functions.

The fraudulent email carried the subject line “Data Breach Notice: Please refresh API Keys as soon as possible,” according to CoinTracking. The company warned customers not to follow links contained in the message while it investigated the compromise of its Brevo account.

Brevo’s findings show that phishing emails represented only part of the activity across the 138 accessed accounts. The attacker exported contacts from 43 accounts, potentially leaving address lists available for use outside Brevo’s own mailing infrastructure.

Trezor is already treating its full newsletter list as potentially known to the attacker, although the company said it had not received confirmation that all 347,000 addresses were exported.

The hardware wallet maker has faced a separate customer data exposure this year involving logistics provider ShipMonk. Trezor initially disclosed in August that information belonging to 13,689 customers had been exposed through the shipping provider.

The scope later increased after Trezor learned that records belonging to approximately 67,000 additional U.S. customers had remained in ShipMonk’s systems. The older records covered purchases made between November 2019 and August 2021 and included names, email addresses, phone numbers, shipping addresses and order numbers.

Trezor said its own systems were not compromised in the ShipMonk incident and no private keys or recovery phrases were exposed. The company had previously received assurances that the older customer records had been deleted before learning on Sept. 2 that they remained stored by the provider.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button